[Git][security-tracker-team/security-tracker][master] Update status for node-ws issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 08:44:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
62fd926d by Salvatore Bonaccorso at 2026-07-30T09:43:13+02:00
Update status for node-ws issues

CVE-2026-62389 got rejected because it is a duplicate of CVE-2026-48779.
Merge useful tracking information from CVE-2026-62389 to CVE-2026-48779.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15209,9 +15209,6 @@ CVE-2026-62683 (File Browser is a file managing interface for uploading, deletin
 	NOT-FOR-US: File Browser
 CVE-2026-62389
 	REJECTED
-	- node-ws 8.21.1+~cs14.19.1-1 (bug #1142271)
-	NOTE: https://github.com/websockets/ws/issues/2331
-	NOTE: Fixed by: https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d (8.21.1)
 CVE-2026-62378 (RustFS Console is a web management console for the RustFS distributed  ...)
 	NOT-FOR-US: RustFS
 CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software. Prior to  ...)
@@ -36734,11 +36731,13 @@ CVE-2026-48782 (Pydantic AI is a Python agent framework for building application
 CVE-2026-48781 (Postiz is an AI social media scheduling tool. In versions prior to 2.2 ...)
 	NOT-FOR-US: Postiz
 CVE-2026-48779 (ws is an open source WebSocket client and server for Node.js. All vers ...)
-	- node-ws 8.21.0+~cs14.19.1-1 (bug #1140429)
+	- node-ws 8.21.0+~cs14.19.1-1 (bug #1140429; bug #1142271)
 	[trixie] - node-ws <no-dsa> (Minor issue)
 	[bookworm] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
 	[bullseye] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
 	NOTE: https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
+	NOTE: https://github.com/websockets/ws/issues/2331
+	NOTE: Fixed by: https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d (8.21.1)
 CVE-2026-48777 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Ve ...)
 	NOT-FOR-US: FileBrowser Quantum
 CVE-2026-48776 (LangGraph Python SDK is used to connect to running LangGraph API serve ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/1b76bda4/attachment.htm>


More information about the debian-security-tracker-commits mailing list